Fake GitHub Lure Spreads AmnesiaStealer on macOS

Security Affairs · High sophistication
Last updated August 14, 2026

Researchers describe AmnesiaStealer, a macOS infostealer spread via a convincing fake GitHub download page that tricks users into pasting a Terminal command. After installation, it uses an “Installer”-style password prompt to capture the Mac login password, steal browser and keychain data, and can even give attackers hidden, live control of the victim’s browser session.

Key findings

  • AmnesiaStealer is distributed via a counterfeit GitHub download page using the ClickFix technique, prompting users to paste a Terminal command instead of clicking a normal download button.
  • The malware presents a native macOS password prompt styled like an Installer dialog and repeatedly prompts until the correct password is entered.
  • Stolen credentials are reused to unlock the keychain and access additional data; the password is also written to disk in cleartext.
  • A third-stage “stream module” can clone the victim’s browser profile and provide attackers live, hidden control of a headless browser session.
  • The lure template appears shared with other macOS stealer campaigns (Atomic Stealer and MacSync), suggesting reused infrastructure.

Who’s being targeted

  • Commonly targeted roles: Developers, Engineering, IT, All macOS users, Security awareness training participants.
  • Affected industries: Technology, Software development, Any organization with macOS endpoints.
  • Attack channels: website.
  • Impersonated: GitHub / a “verified” software publisher on GitHub.

Awareness takeaways

  • Treat any website that asks you to paste a Terminal command as high risk; stop and verify the source through official vendor channels.
  • Do not enter your macOS password into unexpected prompts, especially during “downloads” from the web, and report it to IT/security.
  • Assume stolen passwords can be reused to access more sensitive data (keychain, notes, browser sessions), so rapid reporting matters.

Red flags to watch for

  • A download page asks you to paste a Terminal command rather than using a normal installer/package.
  • The page relies on visual trust signals (e.g., “Verified Publisher” badge) to rush acceptance.
  • An unexpected macOS password prompt appears during a download from a web page.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You land on a dark-themed GitHub page, Octocat logo, “Verified Publisher” badge, looks totally legit. But here’s the trick: instead of a download button, it tells you to paste a Terminal command. That’s the ClickFix move used to drop AmnesiaStealer on macOS. After you run it, a native macOS password box pops up, styled like an Installer. AmnesiaStealer keeps asking until it gets your real Mac password, then reuses it to unlock your keychain and even hijack your browser in the background. Aha test: if a GitHub page tells you to paste a Terminal command or a download triggers an odd password prompt, stop. Don’t enter it, screenshot it and report it to security.

Categories

Similar attacks

Fake LastPass GitHub Drops Rapuncel Stealer

Fake LastPass GitHub Drops Rapuncel Stealer

Attackers impersonated LastPass on GitHub and tricked people searching for the “LastPass Authenticator download” into installing a fake installer. The infection chain used a Microsoft-signed driver to disable many security tools, then deployed an infostealer that stole passwords, crypto wallets,…

September 23, 2026
Fake GitHub Page Tricks Mac Users Into Malware

Fake GitHub Page Tricks Mac Users Into Malware

Researchers found a real macOS malware campaign that uses a fake GitHub download page to convince users to paste a command into Terminal and enter their Mac password. The malware then steals credentials, cookies, and files, and can even turn the victim’s Chromium browser into a remotely controlled…

August 17, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Researchers say a real macOS malware campaign is using “ClickFix” social engineering to trick users into installing an infostealer called AmnesiaStealer. Victims are lured to a counterfeit GitHub download page that encourages them to copy/paste a Terminal command, which then downloads and runs the…

August 14, 2026
Fake “Wavel” Wallet Site Drops PamStealer on Macs

Fake “Wavel” Wallet Site Drops PamStealer on Macs

Researchers report a new PamStealer variant that lures macOS users to a fake cryptocurrency wallet website and tricks them into running a script-based installer. The malware downloads a decryption tool and relies on a live server key exchange, making the real payload harder to analyze and helping…

September 25, 2026
HBO Max Reddit Account Hijacked for ClickFix Malware Ads

HBO Max Reddit Account Hijacked for ClickFix Malware Ads

Attackers took over the verified official HBO Max Reddit account and used it to run a 48-hour wave of malicious ads. The ads sent people to lookalike download sites that tricked them into copying and running commands, leading to information-stealing malware on both macOS and Windows. Researchers…

September 15, 2026